Forum Discussion
removal/disable of tcp timestamp with reference to CVE-2005-0356
removal/disable of tcp timestamp with reference to CVE-2005-0356, please advise is it recommended to remove tcp timestamp on f5 or on the server side to mitigate this vulnerability?
3 Replies
- Brad_Parker
Cirrus
Are you running BigIP v9.0? If not, I don't think you have to worry about this. https://support.f5.com/kb/en-us/solutions/public/4000/700/sol4743.html
- dw_888_212625
Nimbostratus
There seem to be a contradicting statement between the CVE-2005-0356 description and F5’s statement: · the CVE-2005-0356 description in https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2005-0356 states that PAWS used with timestamp option enabled is vulnerable to DoS · in contrast, https://support.f5.com/kb/en-us/solutions/public/8000/000/sol8072.html PAWS can protect against DoS attacks
kindly advise
- Brad_Parker
Cirrus
I suggest you open a support case.
Help guide the future of your DevCentral Community!
What tools do you use to collaborate? (1min - anonymous)Recent Discussions
Related Content
* Getting Started on DevCentral
* Community Guidelines
* Community Terms of Use / EULA
* Community Ranking Explained
* Community Resources
* Contact the DevCentral Team
* Update MFA on account.f5.com